Human Trust Exploitation

Operators approve what the agent shows them. An agent that has been manipulated can present a misleading summary, hide a dangerous step in a long diff, or ask for an approval that means something other than it appears to. OWASP ASI09.

OWASP Agentic Top 10: ASI09 Human-Agent Trust Exploitation

Other agent threat types

Showing 1–2 of 2 threats, newest first

phishing-as-a-servicevoice-AIsocial-engineeringstolen-devicesactivation-lockAI-vishingPhaaSSurface: Human InterfacePropagation: None

AnonyMousKIT is a phishing-as-a-service platform that uses voice AI agents to impersonate Apple support and trick victims into revealing codes needed to unlock stolen iPhones and disable Activation Lock. This is primarily a human-facing social engineering threat that leverages AI voice generation to scale traditional vishing rather than an attack on agent infrastructure or protocols. Severity is high due to real-world financial and privacy harm to victims and the commoditization of AI-driven fraud tooling.

Updated Aug 26, 2026

TOCTOUcomputer-use-agentrace-conditionbrowser-agentChatGPT-OperatorUI-confirmation-bypassASI06 · Memory PoisoningSurface: PlannerPropagation: None

This research describes a time-of-check-to-time-of-use (TOCTOU) attack against computer-use AI agents like ChatGPT Operator, where a malicious page or element changes between the moment the agent evaluates it and the moment it acts, causing the agent (and a supervising human) to click or execute something different from what was reviewed. The author reproduced a previously disclosed Google-reported vulnerability and demonstrated it live at a security conference. This is a legitimate and impactful vulnerability class for autonomous browser/UI-driving agents.

Updated Jul 5, 2026